A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provide a specially crafted input file that triggers the condition, resulting in application crash and denial of service.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 22 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | GPAC Null Pointer Dereference Leading to Denial of Service | |
| Weaknesses | CWE-476 |
Tue, 22 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gpac
Gpac gpac |
|
| Vendors & Products |
Gpac
Gpac gpac |
Tue, 22 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provide a specially crafted input file that triggers the condition, resulting in application crash and denial of service. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-22T19:34:19.789Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88339
No data.
Status : Received
Published: 2026-09-22T20:17:10.130
Modified: 2026-09-22T20:17:10.130
Link: CVE-2026-88339
No data.
OpenCVE Enrichment
Updated: 2026-09-22T21:30:20Z
Weaknesses